{"as_of":"2026-08-12T18:44:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:4ed5624994b05c4c6858c9a03e4af102da448e568d6b6d1249dc868891071a26","coverage":[{"denominator":0,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":0,"source":"paper_references, paper_reference_links","source_observed_at":null,"state":"measured"},{"denominator":63,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":63,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-12T06:34:41.77262+00:00","state":"measured"},{"denominator":63,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":63,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-11T22:41:27.842458Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"pith","source_observed_at":"2026-07-09T10:26:11.073540Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2310.02446","last_updated":"2024-01-27T22:54:52Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2023-10-03T21:30:56Z","title":"Low-Resource Languages Jailbreak GPT-4","version":2},"reference_index":55,"source":"pdf_text","source_observed_at":"2026-05-17T09:24:13.911401Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2310.02446"},"observation_digest":"sha256:0beebff19ec1ae037d6c4ad66f3ee6f97126c41bfdcf5119b08650c54c889437","observation_id":"f61039f2-9233-45ab-8844-f48251c0a235","resolution":{"observed_at":"2026-05-17T09:24:14.144341Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2310.04451","last_updated":"2024-03-20T21:34:56Z","snapshot_observed_at":"2026-08-06T02:57:30.438059Z","submitted_at":"2023-10-03T19:44:37Z","title":"AutoDAN: Generating Stealthy Jailbreak Prompts on Aligned Large Language Models","version":2},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-05-12T16:28:03.996446Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2310.04451"},"observation_digest":"sha256:db9a6b2a82f6fe9d2e938028b80f9154fce5478a5017b6f0b83595a8ee36a942","observation_id":"1e0f96ee-9d05-49d1-922f-9f53fb1f0d00","resolution":{"observed_at":"2026-05-12T16:28:04.036110Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2409.00557","last_updated":"2026-04-29T05:49:57Z","snapshot_observed_at":"2026-08-11T13:05:36.773148Z","submitted_at":"2024-08-31T23:06:12Z","title":"Learning to Ask: When LLM Agents Meet Unclear Instruction","version":4},"reference_index":34,"source":"arxiv_source","source_observed_at":"2026-05-23T21:08:42.276002Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2409.00557"},"observation_digest":"sha256:99986c48f405fb5ac42fb87bfef21ccc2014c7f38048d15abdbe07109235194f","observation_id":"322b7129-6590-4282-a446-b73f7eaf3844","resolution":{"observed_at":"2026-05-23T21:13:28.110741Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-11T22:41:27.842458Z","title":"Gpt-4 is too smart to be safe: Stealthy chat with llms via cipher","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2412.03235","last_updated":"2025-03-25T12:49:43Z","snapshot_observed_at":"2026-08-12T10:06:42.014184Z","submitted_at":"2024-12-04T11:36:37Z","title":"Does Safety Training of LLMs Generalize to Semantically Related Natural Prompts?","version":2},"reference_index":43,"source":"arxiv_source","source_observed_at":"2026-08-11T22:41:27.842458Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2412.03235"},"observation_digest":"sha256:740f28c61ea7ef2d2e6f1a61816a0be00199ddac5a8898aef36600fa0aa5c1ed","observation_id":"2a7ab1d8-fdaa-4c0b-8829-a7f4a30c3e39","resolution":{"observed_at":"2026-08-11T22:41:27.842458Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-11T20:53:38.141085Z","title":"Gpt-4 is too smart to be safe: Stealthy chat with llms via cipher.arXiv preprint arXiv:2308.06463, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2412.05232","last_updated":"2025-07-03T18:06:35Z","snapshot_observed_at":"2026-08-11T20:47:12.032904Z","submitted_at":"2024-12-06T18:02:59Z","title":"LIAR: Leveraging Inference Time Alignment (Best-of-N) to Jailbreak LLMs in Seconds","version":3},"reference_index":77,"source":"pdf_text","source_observed_at":"2026-08-11T20:53:38.141085Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2412.05232"},"observation_digest":"sha256:4b2a88db1f07175be585ab21cd69fd0630fd990b21bf1ae5ece955c635c20f5c","observation_id":"50a81d2a-a775-4586-a196-c270c647630c","resolution":{"observed_at":"2026-08-11T20:53:38.141085Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-11T18:53:15.424756Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2412.10423","last_updated":"2025-04-14T12:52:24Z","snapshot_observed_at":"2026-08-11T18:46:04.704591Z","submitted_at":"2024-12-10T12:42:33Z","title":"Look Before You Leap: Enhancing Attention and Vigilance Regarding Harmful Content with GuidelineLLM","version":2},"reference_index":29,"source":"arxiv_source","source_observed_at":"2026-08-11T18:53:15.424756Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2412.10423"},"observation_digest":"sha256:d5535eb77c1b0c4521c018d01bb98bda7055dabee8020b351a361c5d0d30f0b9","observation_id":"b7d80fef-5017-4c91-aaa1-1129a49dcf14","resolution":{"observed_at":"2026-08-11T18:53:15.424756Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-11T11:17:49.113067Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2412.15623","last_updated":"2024-12-20T07:29:10Z","snapshot_observed_at":"2026-08-11T16:14:27.305117Z","submitted_at":"2024-12-20T07:29:10Z","title":"JailPO: A Novel Black-box Jailbreak Framework via Preference Optimization against Aligned LLMs","version":1},"reference_index":38,"source":"arxiv_source","source_observed_at":"2026-08-11T11:17:49.113067Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2412.15623"},"observation_digest":"sha256:de4798cfe4edb6b7d431959e63ef42e0b1f26c52b2e55bf54868e6a49d863c04","observation_id":"137eadbd-56b4-4846-a67d-8e4022145685","resolution":{"observed_at":"2026-08-11T11:17:49.113067Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-11T05:31:31.710393Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2412.17522","last_updated":"2025-01-05T04:44:32Z","snapshot_observed_at":"2026-08-11T19:02:05.325707Z","submitted_at":"2024-12-23T12:44:54Z","title":"DiffusionAttacker: Diffusion-Driven Prompt Manipulation for LLM Jailbreak","version":2},"reference_index":39,"source":"arxiv_source","source_observed_at":"2026-08-11T05:31:31.710393Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2412.17522"},"observation_digest":"sha256:f8b78c9806aebc2026d351a2a757be5de532deeb0061027909a660154bcd9486","observation_id":"51edbe05-782d-44f1-9cf5-0b0c48e7f1b8","resolution":{"observed_at":"2026-08-11T05:31:31.710393Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-10T20:54:02.524772Z","title":"Gpt-4 is too smart to be safe: Stealthy chat with llms via cipher","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.07124","last_updated":"2025-01-17T09:39:17Z","snapshot_observed_at":"2026-08-10T22:14:07.704280Z","submitted_at":"2025-01-13T08:26:43Z","title":"LLM360 K2: Building a 65B 360-Open-Source Large Language Model from Scratch","version":3},"reference_index":155,"source":"arxiv_source","source_observed_at":"2026-08-10T20:54:02.524772Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2501.07124"},"observation_digest":"sha256:7ffd9e25d7ac4b49dac5cbd21d2276ca503fcd43962009460c062b3c47249b16","observation_id":"b821d2a3-1ac4-4adc-a409-77e24fda3655","resolution":{"observed_at":"2026-08-10T20:54:02.524772Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-10T20:35:52.881332Z","title":"Gpt-4 is too smart to be safe: Stealthy chat with llms via cipher","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.07959","last_updated":"2025-02-01T09:30:34Z","snapshot_observed_at":"2026-08-12T00:45:00.001520Z","submitted_at":"2025-01-14T09:23:30Z","title":"Self-Instruct Few-Shot Jailbreaking: Decompose the Attack into Pattern and Behavior Learning","version":2},"reference_index":48,"source":"pdf_text","source_observed_at":"2026-08-10T20:35:52.881332Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2501.07959"},"observation_digest":"sha256:402ed4276765aa97aad08b8105c91e77d1b69fb4a01bb39b344fb77d92f10211","observation_id":"095ec9a2-ea40-4352-a2c7-27ea35e465f3","resolution":{"observed_at":"2026-08-10T20:35:52.881332Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-10T15:26:44.981699Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.14073","last_updated":"2025-02-18T05:02:09Z","snapshot_observed_at":"2026-08-10T15:21:42.008087Z","submitted_at":"2025-01-23T20:20:20Z","title":"LLMs are Vulnerable to Malicious Prompts Disguised as Scientific Language","version":2},"reference_index":51,"source":"arxiv_source","source_observed_at":"2026-08-10T15:26:44.981699Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2501.14073"},"observation_digest":"sha256:238ac8bfdd8c2a03ac006390924e000e06c563cb062abd3cb7764144b4d1ad5b","observation_id":"d1729677-0533-44d4-922b-4874f4d38f52","resolution":{"observed_at":"2026-08-10T15:26:44.981699Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-10T11:12:44.716762Z","title":"Preprint, arXiv:2308.06463","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2501.16727","last_updated":"2025-01-30T16:17:56Z","snapshot_observed_at":"2026-08-11T20:11:27.909572Z","submitted_at":"2025-01-28T06:07:58Z","title":"xJailbreak: Representation Space Guided Reinforcement Learning for Interpretable LLM Jailbreaking","version":2},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-10T11:12:44.716762Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2501.16727"},"observation_digest":"sha256:a2e6fce382d8e597a0850a4edc9596dcb47f689da39a19a3a6be7f9cbfd9478e","observation_id":"24215a34-9598-4fcd-a458-a9cae85f5bea","resolution":{"observed_at":"2026-08-10T11:12:44.716762Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-10T00:12:04.968909Z","title":"Gpt-4 is too smart to be safe: Stealthy chat with llms via cipher","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2501.18280","last_updated":"2025-05-17T04:37:43Z","snapshot_observed_at":"2026-08-11T14:23:02.047375Z","submitted_at":"2025-01-30T11:37:40Z","title":"Jailbreaking LLMs' Safeguard with Universal Magic Words for Text Embedding Models","version":3},"reference_index":44,"source":"pdf_text","source_observed_at":"2026-08-10T00:12:04.968909Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2501.18280"},"observation_digest":"sha256:118a7f84eb98e272a8eaaa9f40d97ce515d70c5f8606e540b56846993d6d99b8","observation_id":"c561d7ab-4da3-4796-bef4-5b3ed7ffc3bd","resolution":{"observed_at":"2026-08-10T00:12:04.968909Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-09T10:29:50.133416Z","title":"Available: https://arxiv.org/abs/2308.06463","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2502.02960","last_updated":"2025-02-05T07:54:07Z","snapshot_observed_at":"2026-08-11T14:26:02.458624Z","submitted_at":"2025-02-05T07:54:07Z","title":"Large Language Model Adversarial Landscape Through the Lens of Attack Objectives","version":1},"reference_index":2024,"source":"pdf_text","source_observed_at":"2026-08-09T10:29:50.133416Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2502.02960"},"observation_digest":"sha256:5a7a5fadde7d46085ec61ecf33423e30a6ae132b1cb77351095d1797a14af3b1","observation_id":"ed493799-d566-405d-aa80-3f587e1ba4f4","resolution":{"observed_at":"2026-08-09T10:29:50.133416Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-08T23:50:36.202058Z","title":"Gpt-4 is too smart to be safe: Stealthy chat with llms via cipher","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2502.04040","last_updated":"2025-05-30T09:43:42Z","snapshot_observed_at":"2026-08-10T18:19:42.295295Z","submitted_at":"2025-02-06T13:01:44Z","title":"Safety Reasoning with Guidelines","version":2},"reference_index":70,"source":"arxiv_source","source_observed_at":"2026-08-08T23:50:36.202058Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2502.04040"},"observation_digest":"sha256:77f284b9a0c3dc634bde10cc7d98886934f45c5dc17b4a8431329aaa862a8d81","observation_id":"42c9a326-b592-4675-b531-0c2f61ac1e75","resolution":{"observed_at":"2026-08-08T23:50:36.202058Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2502.05206","last_updated":"2026-04-14T16:10:41Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2025-02-02T05:14:22Z","title":"Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety","version":6},"reference_index":72,"source":"pdf_text","source_observed_at":"2026-05-23T04:39:04.591722Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2502.05206"},"observation_digest":"sha256:347d55ed3185c8754c2cd038868d825c3aba5a23acc48138b4b832a1f23a8d77","observation_id":"f6012ba0-abe9-46d9-86b0-fa47570d8577","resolution":{"observed_at":"2026-05-23T04:42:33.940336Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-08T17:02:47.493991Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2502.09638","last_updated":"2025-05-29T06:12:00Z","snapshot_observed_at":"2026-08-09T01:40:08.338849Z","submitted_at":"2025-02-09T20:49:16Z","title":"Jailbreaking to Jailbreak","version":2},"reference_index":51,"source":"pdf_text","source_observed_at":"2026-08-08T17:02:47.493991Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2502.09638"},"observation_digest":"sha256:dbb2e72435f3a23d8aa5b447603fa2742d6c11cca98ad4b8d12230ee8c4324cf","observation_id":"d770caef-559f-473c-ad9e-b1bdc2ad2504","resolution":{"observed_at":"2026-08-08T17:02:47.493991Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-07T15:08:13.720278Z","title":null,"venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2505.16241","last_updated":"2025-05-26T02:28:07Z","snapshot_observed_at":"2026-08-07T21:56:02.136924Z","submitted_at":"2025-05-22T05:19:42Z","title":"Three Minds, One Legend: Jailbreak Large Reasoning Model with Adaptive Stacked Ciphers","version":3},"reference_index":38,"source":"arxiv_source","source_observed_at":"2026-08-07T15:08:13.720278Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2505.16241"},"observation_digest":"sha256:faf2c9669c3c7d606f421682aa912f579d5580fa62a707b448a666ac88a5e793","observation_id":"25844ae7-1cff-4366-a129-75d7593c59d1","resolution":{"observed_at":"2026-08-07T15:08:13.720278Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-07T14:00:09.433962Z","title":"Gpt-4 is too smart to be safe: Stealthy chat with llms via cipher","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.20259","last_updated":"2025-05-26T17:40:40Z","snapshot_observed_at":"2026-08-10T01:20:47.147597Z","submitted_at":"2025-05-26T17:40:40Z","title":"Lifelong Safety Alignment for Language Models","version":1},"reference_index":59,"source":"pdf_text","source_observed_at":"2026-08-07T14:00:09.433962Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2505.20259"},"observation_digest":"sha256:f4188625b402e82b4c953a51ca28f05c6f6a1cd121247b49176e61c1811fa49e","observation_id":"00eaeda2-fadc-4cff-8b0c-0c3331b6c350","resolution":{"observed_at":"2026-08-07T14:00:09.433962Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-07T14:01:11.295701Z","title":"Gpt-4 is too smart to be safe: Stealthy chat with llms via cipher","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.21556","last_updated":"2025-05-26T17:27:32Z","snapshot_observed_at":"2026-08-11T03:01:04.883037Z","submitted_at":"2025-05-26T17:27:32Z","title":"Benign-to-Toxic Jailbreaking: Inducing Harmful Responses from Harmless Prompts","version":1},"reference_index":61,"source":"pdf_text","source_observed_at":"2026-08-07T14:01:11.295701Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2505.21556"},"observation_digest":"sha256:8a9e5802bfa45661b30a518451de5950524067daa3f747ebe5f22b2a78af45fc","observation_id":"5c8b3860-2fa6-4cd5-a27d-726d7a764bc8","resolution":{"observed_at":"2026-08-07T14:01:11.295701Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-07T12:34:35.156845Z","title":"Gpt-4 is too smart to be safe: Stealthy chat with llms via cipher.arXiv preprint arXiv:2308.06463, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.24232","last_updated":"2025-05-30T05:48:50Z","snapshot_observed_at":"2026-08-11T22:57:38.865873Z","submitted_at":"2025-05-30T05:48:50Z","title":"From Hallucinations to Jailbreaks: Rethinking the Vulnerability of Large Foundation Models","version":1},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-07T12:34:35.156845Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2505.24232"},"observation_digest":"sha256:80c934834e7ff93635afa14646458521ad0073acfbddc96c9a0730120466e081","observation_id":"25ce4ff6-5ffe-4b86-864f-aa98df872c3b","resolution":{"observed_at":"2026-08-07T12:34:35.156845Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-07T12:35:23.203550Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.24369","last_updated":"2025-05-30T09:02:07Z","snapshot_observed_at":"2026-08-09T16:12:29.442194Z","submitted_at":"2025-05-30T09:02:07Z","title":"Adversarial Preference Learning for Robust LLM Alignment","version":1},"reference_index":42,"source":"arxiv_source","source_observed_at":"2026-08-07T12:35:23.203550Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2505.24369"},"observation_digest":"sha256:6bca1871f27f062976dcf57ed43aa33dabee7f43bcff5ff665beeb3581767bf1","observation_id":"9be9595b-16d4-4dec-87c0-bc76a894d4a5","resolution":{"observed_at":"2026-08-07T12:35:23.203550Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-07T12:04:47.378971Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.00668","last_updated":"2025-05-31T18:38:23Z","snapshot_observed_at":"2026-08-08T14:13:24.402413Z","submitted_at":"2025-05-31T18:38:23Z","title":"SafeTy Reasoning Elicitation Alignment for Multi-Turn Dialogues","version":1},"reference_index":24,"source":"arxiv_source","source_observed_at":"2026-08-07T12:04:47.378971Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2506.00668"},"observation_digest":"sha256:74fddb69ab74270a31ec8da207c268f108997931f140257fffcb466b78d41f6e","observation_id":"5cffd341-abfa-4495-a903-16bbe2c8b757","resolution":{"observed_at":"2026-08-07T12:04:47.378971Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-07T11:51:30.970995Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.01307","last_updated":"2025-06-02T04:33:56Z","snapshot_observed_at":"2026-08-12T11:16:49.908752Z","submitted_at":"2025-06-02T04:33:56Z","title":"Align is not Enough: Multimodal Universal Jailbreak Attack against Multimodal Large Language Models","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-07T11:51:30.970995Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2506.01307"},"observation_digest":"sha256:b4a932cb3a126316858605ee510ed34d229f973f5a5c52216d17444e0af1b254","observation_id":"85f15e9a-2344-4c10-ad7f-c18cdf49a089","resolution":{"observed_at":"2026-08-07T11:51:30.970995Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-07T10:17:27.004439Z","title":"Gpt-4 is too smart to be safe: Stealthy chat with llms via cipher,","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.11094","last_updated":"2025-10-30T06:22:33Z","snapshot_observed_at":"2026-08-07T10:11:06.747781Z","submitted_at":"2025-06-06T05:50:50Z","title":"The Scales of Justitia: A Comprehensive Survey on Safety Evaluation of LLMs","version":2},"reference_index":134,"source":"pdf_text","source_observed_at":"2026-08-07T10:17:27.004439Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2506.11094"},"observation_digest":"sha256:f6bb49b1688ebd2ca0b12d0929119a192135ffdb074cf4eda85c1dc810c1c286","observation_id":"30ef75e3-d5d3-4d24-9092-8d1f164173d8","resolution":{"observed_at":"2026-08-07T10:17:27.004439Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-07T01:02:31.303381Z","title":"Gpt-4 is too smart to be safe: Stealthy chat with llms via cipher","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.12274","last_updated":"2025-06-13T23:03:11Z","snapshot_observed_at":"2026-08-12T18:03:15.878318Z","submitted_at":"2025-06-13T23:03:11Z","title":"InfoFlood: Jailbreaking Large Language Models with Information Overload","version":1},"reference_index":42,"source":"arxiv_source","source_observed_at":"2026-08-07T01:02:31.303381Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2506.12274"},"observation_digest":"sha256:2022d28b05ad191f3f07e86bec84429ed2113f8566cfc7f61f9bbb155100e18d","observation_id":"94e37423-7f20-4f0d-a15e-2c7c1724b829","resolution":{"observed_at":"2026-08-07T01:02:31.303381Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2506.12382","last_updated":"2026-04-27T08:32:16Z","snapshot_observed_at":"2026-08-02T04:53:57.144183Z","submitted_at":"2025-06-14T07:31:52Z","title":"Exploring the Secondary Risks of Large Language Models","version":5},"reference_index":52,"source":"pdf_text","source_observed_at":"2026-05-19T09:40:58.067398Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2506.12382"},"observation_digest":"sha256:002b6185a76b7b53503cbae5b1f739f6cc8d307e263ac3987f102915e0c2f726","observation_id":"df86a486-20dc-4ec7-a603-7be884eef3dc","resolution":{"observed_at":"2026-05-19T09:42:14.014272Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-07T00:32:36.731379Z","title":"Gpt-4 is too smart to be safe: Stealthy chat with llms via cipher.arXiv preprint arXiv:2308.06463, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.13666","last_updated":"2025-06-16T16:24:31Z","snapshot_observed_at":"2026-08-07T00:25:36.770856Z","submitted_at":"2025-06-16T16:24:31Z","title":"We Should Identify and Mitigate Third-Party Safety Risks in MCP-Powered Agent Systems","version":1},"reference_index":93,"source":"pdf_text","source_observed_at":"2026-08-07T00:32:36.731379Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2506.13666"},"observation_digest":"sha256:0acac83158f5a0ce84a8aef012b355da07e07cb1870dcb1a8ffb9f931aa80df2","observation_id":"1524d6e6-286a-43ba-93ef-3b2fef453951","resolution":{"observed_at":"2026-08-07T00:32:36.731379Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-06T23:42:42.971360Z","title":"arXiv preprint arXiv:2308.06463 (2023)","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2506.16760","last_updated":"2025-06-20T05:30:25Z","snapshot_observed_at":"2026-08-08T20:36:58.393923Z","submitted_at":"2025-06-20T05:30:25Z","title":"Cross-Modal Obfuscation for Jailbreak Attacks on Large Vision-Language Models","version":1},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-08-06T23:42:42.971360Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2506.16760"},"observation_digest":"sha256:6fb0a96da3dff3b3c559311c90cf67364ed8a0c619be0473b6d7e9a2a397675c","observation_id":"820d8f86-6714-42f3-8fd9-c2763326728f","resolution":{"observed_at":"2026-08-06T23:42:42.971360Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-06T18:28:46.286783Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2507.08898","last_updated":"2025-07-17T08:01:44Z","snapshot_observed_at":"2026-08-08T14:51:56.908190Z","submitted_at":"2025-07-11T05:15:35Z","title":"SEALGuard: Safeguarding the Multilingual Conversations in Southeast Asian Languages for LLM Software Systems","version":3},"reference_index":56,"source":"pdf_text","source_observed_at":"2026-08-06T18:28:46.286783Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2507.08898"},"observation_digest":"sha256:43d6442016264e762dad084ce93a6e100b10250b44989c8b0c45feb1e6078041","observation_id":"7d626332-ac7c-4139-a90b-8b60aa8ecab5","resolution":{"observed_at":"2026-08-06T18:28:46.286783Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-06T16:28:53.451033Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2507.13474","last_updated":"2025-07-17T18:33:50Z","snapshot_observed_at":"2026-08-09T05:14:52.776386Z","submitted_at":"2025-07-17T18:33:50Z","title":"Paper Summary Attack: Jailbreaking LLMs through LLM Safety Papers","version":1},"reference_index":39,"source":"arxiv_source","source_observed_at":"2026-08-06T16:28:53.451033Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2507.13474"},"observation_digest":"sha256:737a2dfc2f598cadfe6d77c341e6b99c6c6881b596f0a911478d83cbc3f92ef4","observation_id":"a938959c-9abd-4204-8835-ff1968fc4e5d","resolution":{"observed_at":"2026-08-06T16:28:53.451033Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-06T05:43:39.612853Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2508.01306","last_updated":"2025-08-02T10:36:01Z","snapshot_observed_at":"2026-08-11T02:10:38.473408Z","submitted_at":"2025-08-02T10:36:01Z","title":"PUZZLED: Jailbreaking LLMs through Word-Based Puzzles","version":1},"reference_index":22,"source":"arxiv_source","source_observed_at":"2026-08-06T05:43:39.612853Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2508.01306"},"observation_digest":"sha256:8d3dbba4c45bd54fd625f21db20e231357e133fdb326f6d26031a32933f70d2c","observation_id":"af484381-9d39-4ae6-8e77-2f660dd1f53c","resolution":{"observed_at":"2026-08-06T05:43:39.612853Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-05T20:31:39.676177Z","title":"Gpt-4 is too smart to be safe: Stealthy chat with llms via cipher","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2508.10404","last_updated":"2025-08-14T07:12:44Z","snapshot_observed_at":"2026-08-08T02:31:17.622343Z","submitted_at":"2025-08-14T07:12:44Z","title":"Layer-Wise Perturbations via Sparse Autoencoders for Adversarial Text Generation","version":1},"reference_index":72,"source":"pdf_text","source_observed_at":"2026-08-05T20:31:39.676177Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2508.10404"},"observation_digest":"sha256:c0a38ee6e1823e4017fde2c32ef1c7fe4dcb3dec12e383b1ec17a7df110f2cc7","observation_id":"7a546f1b-868d-443b-9131-adc1338483e6","resolution":{"observed_at":"2026-08-05T20:31:39.676177Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-05T16:00:52.279969Z","title":"Gpt-4 is too smart to be safe: Stealthy chat with llms via cipher, 2024","venue":null,"work_id":null,"year":2024},"citing_paper":{"arxiv_id":"2508.19445","last_updated":"2026-06-16T17:34:06Z","snapshot_observed_at":"2026-08-08T05:25:02.825611Z","submitted_at":"2025-08-26T21:36:45Z","title":"On Surjectivity of Neural Networks: Can you elicit any behavior from your model?","version":3},"reference_index":110,"source":"arxiv_source","source_observed_at":"2026-08-05T16:00:52.279969Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2508.19445"},"observation_digest":"sha256:5625e5fd280c44e3be3d95b36eb74a595e5026380110771e179f63de56b8b735","observation_id":"81dec6fa-9497-4c47-b32e-c685f32f3f44","resolution":{"observed_at":"2026-08-05T16:00:52.279969Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2508.20325","last_updated":"2026-05-11T14:12:43Z","snapshot_observed_at":"2026-07-06T22:19:48.389341Z","submitted_at":"2025-08-28T00:07:10Z","title":"GUARD: Guideline Upholding Test through Adaptive Role-play and Jailbreak Diagnostics for LLMs","version":3},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-05-18T21:34:51.665401Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2508.20325"},"observation_digest":"sha256:56cb9c8d102aac3d171975cc849ea7593077251d13599844afd31aa8503e35bd","observation_id":"9f740cc8-976e-4e1b-bdac-fa4eb26f8472","resolution":{"observed_at":"2026-05-18T21:36:52.497769Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-05T13:42:44.381806Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2509.00391","last_updated":"2025-08-30T07:04:29Z","snapshot_observed_at":"2026-08-07T20:54:59.881714Z","submitted_at":"2025-08-30T07:04:29Z","title":"The Resurgence of GCG Adversarial Attacks on Large Language Models","version":1},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-08-05T13:42:44.381806Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2509.00391"},"observation_digest":"sha256:102237b8660fe002c2e516d2ffc58804693da941ec2345a19431239661730e33","observation_id":"f96a562b-0d45-4976-86b5-95dfd84493ac","resolution":{"observed_at":"2026-08-05T13:42:44.381806Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-04T17:27:25.863629Z","title":"Andy Zou, Zifan Wang, J","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2509.10931","last_updated":"2025-09-13T18:07:56Z","snapshot_observed_at":"2026-08-12T13:20:19.742516Z","submitted_at":"2025-09-13T18:07:56Z","title":"Harmful Prompt Laundering: Jailbreaking LLMs with Abductive Styles and Symbolic Encoding","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-04T17:27:25.863629Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2509.10931"},"observation_digest":"sha256:990366557e20e83d740f619679fa8624074f68a0025798fbd3eecf348a6a1a70","observation_id":"e0e95381-fe18-4746-a919-30ebdb36348b","resolution":{"observed_at":"2026-08-04T17:27:25.863629Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-04T17:09:24.212002Z","title":null,"venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2509.11141","last_updated":"2025-09-14T07:21:44Z","snapshot_observed_at":"2026-08-12T10:33:20.955682Z","submitted_at":"2025-09-14T07:21:44Z","title":"When Smiley Turns Hostile: Interpreting How Emojis Trigger LLMs' Toxicity","version":1},"reference_index":54,"source":"arxiv_source","source_observed_at":"2026-08-04T17:09:24.212002Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2509.11141"},"observation_digest":"sha256:62c26962c66cd3389a339b768a0f39ce8b10ff7c72c7e095e275cdae26630acd","observation_id":"14e021f4-b94e-4ddc-addd-d14cec6975ed","resolution":{"observed_at":"2026-08-04T17:09:24.212002Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2510.07239","last_updated":"2026-05-17T13:01:38Z","snapshot_observed_at":"2026-08-02T19:25:51.433055Z","submitted_at":"2025-10-08T17:06:20Z","title":"Red-Bandit: Test-Time Adaptation for LLM Red-Teaming via Bandit-Guided LoRA Experts","version":2},"reference_index":47,"source":"pdf_text","source_observed_at":"2026-05-21T20:53:58.198974Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2510.07239"},"observation_digest":"sha256:a05cb5cc6bbdce3f5ee8bbd4859a1b3b9c4bb006dc871d8c7d8f06d378b6512e","observation_id":"43b20aaf-a445-4c4a-8f84-a697768cd714","resolution":{"observed_at":"2026-05-21T20:54:21.564674Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2510.10073","last_updated":"2026-04-14T02:53:37Z","snapshot_observed_at":"2026-08-10T21:16:04.795126Z","submitted_at":"2025-10-11T07:18:12Z","title":"SecureWebArena: A Holistic Security Evaluation Benchmark for LVLM-based Web Agents","version":2},"reference_index":62,"source":"pdf_text","source_observed_at":"2026-05-18T08:14:51.102085Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2510.10073"},"observation_digest":"sha256:bbd8ef036e399a49ef458bde521e019c1adf0ed90e9461c82329951251ac2c44","observation_id":"c59c361b-10ba-4e26-8941-72637653d8ee","resolution":{"observed_at":"2026-05-18T08:16:06.624171Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2604.07655","last_updated":"2026-04-08T23:47:29Z","snapshot_observed_at":"2026-08-02T09:41:13.361711Z","submitted_at":"2026-04-08T23:47:29Z","title":"Guardian-as-an-Advisor: Advancing Next-Generation Guardian Models for Trustworthy LLMs","version":1},"reference_index":87,"source":"pdf_text","source_observed_at":"2026-05-10T17:27:13.339411Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2604.07655"},"observation_digest":"sha256:5a66783d736331785ae71cd64532469893c8ddcc4829d80e7915b6fca035006f","observation_id":"9baeea80-9417-4dea-bfe7-8ccb1a57a5d6","resolution":{"observed_at":"2026-05-11T06:46:34.844765Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2604.07727","last_updated":"2026-04-09T02:22:44Z","snapshot_observed_at":"2026-08-11T01:30:41.906955Z","submitted_at":"2026-04-09T02:22:44Z","title":"TrajGuard: Streaming Hidden-state Trajectory Detection for Decoding-time Jailbreak Defense","version":1},"reference_index":44,"source":"arxiv_source","source_observed_at":"2026-05-10T18:26:19.922383Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2604.07727"},"observation_digest":"sha256:ed59bbe5563abc865480634b034adc599a6a0cb86d6b6938e86fa6948a6291d4","observation_id":"5140e315-47f6-4d25-9f5a-b37147cfd572","resolution":{"observed_at":"2026-05-11T00:35:50.772336Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2604.14808","last_updated":"2026-04-16T09:31:36Z","snapshot_observed_at":"2026-08-11T20:41:36.906334Z","submitted_at":"2026-04-16T09:31:36Z","title":"Modeling LLM Unlearning as an Asymmetric Two-Task Learning Problem","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-05-10T11:38:59.190582Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2604.14808"},"observation_digest":"sha256:9f6f66819a9189a672c04f048f1da0d66d2498f51d8874ed700167db4d92bea3","observation_id":"14a35fdd-318c-4514-9c66-5ac8d4e0bb2d","resolution":{"observed_at":"2026-05-10T11:40:18.978189Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2604.22089","last_updated":"2026-04-23T21:41:09Z","snapshot_observed_at":"2026-07-06T23:08:33.204647Z","submitted_at":"2026-04-23T21:41:09Z","title":"Ethics Testing: Proactive Identification of Generative AI System Harms","version":1},"reference_index":81,"source":"pdf_text","source_observed_at":"2026-05-09T20:49:22.147548Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2604.22089"},"observation_digest":"sha256:bc75fd445b54871983cc3be48e8ca5b81776b33dec1a675ec4119de8dcad598c","observation_id":"159dede1-ceaf-4d62-8314-a2c29bc928c4","resolution":{"observed_at":"2026-05-11T14:56:07.935256Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2605.00236","last_updated":"2026-04-30T21:15:38Z","snapshot_observed_at":"2026-08-11T08:40:01.863341Z","submitted_at":"2026-04-30T21:15:38Z","title":"Attention Is Where You Attack","version":1},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-05-09T19:54:41.445447Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2605.00236"},"observation_digest":"sha256:eb7d86f634d2dbc854462cd2a26c5ea49c810d4b53c4305047e25a317b84c67f","observation_id":"e937ce11-2df3-4700-ab24-536993c41fb5","resolution":{"observed_at":"2026-05-11T15:26:23.715009Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2605.00267","last_updated":"2026-05-04T18:25:35Z","snapshot_observed_at":"2026-08-12T14:46:07.258711Z","submitted_at":"2026-04-30T22:04:10Z","title":"Jailbroken Frontier Models Retain Their Capabilities","version":2},"reference_index":3,"source":"arxiv_source","source_observed_at":"2026-05-09T20:00:08.368799Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2605.00267"},"observation_digest":"sha256:be7566ccde4cf1e28ea1c4c1920d3cbe6c006e157580a3c79e80968acf3b841b","observation_id":"0e6f93ff-4ae1-4c0d-83d4-582bcf692458","resolution":{"observed_at":"2026-05-11T15:26:09.757309Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2605.03441","last_updated":"2026-05-05T07:25:33Z","snapshot_observed_at":"2026-08-10T21:29:00.284608Z","submitted_at":"2026-05-05T07:25:33Z","title":"Exposing LLM Safety Gaps Through Mathematical Encoding:New Attacks and Systematic Analysis","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-05-07T15:48:54.277233Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2605.03441"},"observation_digest":"sha256:f3012c90d63640de9514c3ddc9921f66ef8d08f1fe2030913bbffd8cdae81553","observation_id":"45fd79a9-dde3-49b0-b5d6-d309292020fb","resolution":{"observed_at":"2026-05-12T10:51:31.123072Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2605.07032","last_updated":"2026-07-20T17:49:20Z","snapshot_observed_at":"2026-08-02T14:41:04.240876Z","submitted_at":"2026-05-07T23:22:07Z","title":"A Systematic Investigation of RL-Jailbreaking in LLMs","version":1},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-05-11T01:32:42.151644Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2605.07032"},"observation_digest":"sha256:320a967b33c8f2d5bc1e017ae0969f59e7e8407612ce5900d501018972293ace","observation_id":"08daedea-83f2-4830-9833-275470a56b54","resolution":{"observed_at":"2026-05-11T01:40:52.578620Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2605.07032","last_updated":"2026-07-20T17:49:20Z","snapshot_observed_at":"2026-08-02T14:41:04.240876Z","submitted_at":"2026-05-07T23:22:07Z","title":"A Systematic Investigation of RL-Jailbreaking in LLMs","version":2},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-06-30T22:59:07.861941Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2605.07032"},"observation_digest":"sha256:19943ef3690b9748bb6e807cbef8046e79797bdf268ff4ba14423a95a95f5aa6","observation_id":"920ca7fe-d442-40cd-8bd1-6f12fb1373c8","resolution":{"observed_at":"2026-07-01T13:35:46.496963Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-02T14:41:07.326795Z","title":"GPT-4 is too smart to be safe: Stealthy Chat with LLMs via Cipher","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2605.07032","last_updated":"2026-07-20T17:49:20Z","snapshot_observed_at":"2026-08-02T14:41:04.240876Z","submitted_at":"2026-05-07T23:22:07Z","title":"A Systematic Investigation of RL-Jailbreaking in LLMs","version":3},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-02T14:41:07.326795Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2605.07032"},"observation_digest":"sha256:80c87317247d8c1b13726d0d27d7a46ea34664c47bc838b1a317a29aa6a8625e","observation_id":"f3c9c04b-a4f8-45eb-aa48-d3ad2a6e10f4","resolution":{"observed_at":"2026-08-02T14:41:07.326795Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2605.16471","last_updated":"2026-05-15T13:53:02Z","snapshot_observed_at":"2026-07-06T23:27:38.955917Z","submitted_at":"2026-05-15T13:53:02Z","title":"From AI-Generated Content to Agentic Action: Security and Safety Threats in Generative AI","version":1},"reference_index":151,"source":"pdf_text","source_observed_at":"2026-05-20T18:08:24.901025Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2605.16471"},"observation_digest":"sha256:1088bdf3eea914f33948a9a126967545281e5b1810e16fe3807b44e72aa046ae","observation_id":"78ba9926-cbda-44ab-b93d-dd356a0f8857","resolution":{"observed_at":"2026-05-20T18:08:50.682304Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2605.21362","last_updated":"2026-05-20T16:27:00Z","snapshot_observed_at":"2026-07-06T23:31:51.443407Z","submitted_at":"2026-05-20T16:27:00Z","title":"LASH: Adaptive Semantic Hybridization for Black-Box Jailbreaking of Large Language Models","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-05-21T04:48:19.926845Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2605.21362"},"observation_digest":"sha256:a597286df084cc027019c6ccba662bcbfdb67a4cbd659e374a3f9482d1907c4c","observation_id":"00feaf7b-eb0f-48c4-afd2-5ae4f0ea2e8c","resolution":{"observed_at":"2026-05-21T04:49:35.515127Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2605.21674","last_updated":"2026-05-20T19:31:07Z","snapshot_observed_at":"2026-07-06T23:32:05.693503Z","submitted_at":"2026-05-20T19:31:07Z","title":"Adversarial Reframing: A Framework for Targeted Generation in Language Models","version":1},"reference_index":59,"source":"pdf_text","source_observed_at":"2026-05-22T09:35:51.862736Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2605.21674"},"observation_digest":"sha256:a1aac941aeba2a5bf6e517624241382e98dc0833fcba5e66ae1bbdfd3ceea9a5","observation_id":"47ee0339-5dd1-488d-a45e-0832c8ee7588","resolution":{"observed_at":"2026-05-22T09:36:20.970501Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-13T08:47:59.151393Z","title":"always prioritize safety; refuse to answer if a query could be unsafe","venue":null,"work_id":null,"year":2025},"citing_paper":{"arxiv_id":"2605.27375","last_updated":"2026-04-08T09:20:22Z","snapshot_observed_at":"2026-08-12T03:43:36.374748Z","submitted_at":"2026-04-08T09:20:22Z","title":"LCO: LLM-based Constraint Optimization for Safer Agentic LLMs in Real-world Tasks","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-07-13T08:47:59.151393Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2605.27375"},"observation_digest":"sha256:6455244834d961c66a37cc33205890e79239c39a4c0c052326b8ef5dd8da6935","observation_id":"41c38ef4-9f73-41ee-be10-84ed9c64bd34","resolution":{"observed_at":"2026-07-13T08:47:59.151393Z","resolver_source":null,"status":"malformed_identifier"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2605.28030","last_updated":"2026-05-27T06:36:22Z","snapshot_observed_at":"2026-08-07T03:38:26.044946Z","submitted_at":"2026-05-27T06:36:22Z","title":"SPARD: Defending Harmful Fine-Tuning Attack via Safety Projection with Relevance-Diversity Data Selection","version":1},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-06-29T13:49:56.311711Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2605.28030"},"observation_digest":"sha256:a15338b92a844522c59204fa2148eb432e8c9a59e55c91fe5be4beb76e6b64a3","observation_id":"141d8132-5853-478d-a121-92d13b184982","resolution":{"observed_at":"2026-06-29T13:53:28.684601Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2605.29667","last_updated":"2026-05-28T09:28:51Z","snapshot_observed_at":"2026-08-08T05:28:29.807879Z","submitted_at":"2026-05-28T09:28:51Z","title":"Beyond English and Evasion: A Human-Annotated Multi-Domain Benchmark for High-Stakes LLM Safety Evaluation in Chinese","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-06-29T07:55:07.161442Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2605.29667"},"observation_digest":"sha256:595a262a99e0ed61fe0923654af55da98fe2865b4d07e501b9c0136611ddcf7c","observation_id":"55b51ddd-e3b9-44f3-9062-e9740a64b972","resolution":{"observed_at":"2026-06-29T08:03:14.660791Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2606.05609","last_updated":"2026-06-04T02:31:29Z","snapshot_observed_at":"2026-08-05T14:48:48.513078Z","submitted_at":"2026-06-04T02:31:29Z","title":"SlotGCG: Exploiting the Positional Vulnerability in LLMs for Jailbreak Attacks","version":1},"reference_index":29,"source":"arxiv_source","source_observed_at":"2026-06-28T01:16:07.252429Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2606.05609"},"observation_digest":"sha256:5f36951936d48bee10824e29e693c018bb1c612b26b27670c6c9889f398b0093","observation_id":"c5a5d93a-df35-44b3-85c6-8f4a8edbbbe0","resolution":{"observed_at":"2026-07-02T13:26:59.318146Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2606.05614","last_updated":"2026-06-04T02:36:41Z","snapshot_observed_at":"2026-08-06T05:01:48.088482Z","submitted_at":"2026-06-04T02:36:41Z","title":"Safety Paradox: How Enhanced Safety Awareness Leaves LLMs Vulnerable to Posterior Attack","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-06-28T01:59:37.573954Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2606.05614"},"observation_digest":"sha256:62dd3c5f3257a5bbe58968fbc786193f3466ce0e68e2dffbd6e93022e4d1e58b","observation_id":"769321d3-7363-4023-a416-b65a0668cf49","resolution":{"observed_at":"2026-07-02T12:36:56.906206Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2606.19887","last_updated":"2026-06-24T07:42:32Z","snapshot_observed_at":"2026-07-06T23:55:05.932014Z","submitted_at":"2026-06-18T07:46:18Z","title":"FinRED: An Expert-Guided Benchmark Generation and Evaluation Framework for Financial LLM Red-Teaming","version":2},"reference_index":45,"source":"pdf_text","source_observed_at":"2026-06-26T17:11:40.088809Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2606.19887"},"observation_digest":"sha256:78e8301bf95e050a98b3ab66a640747aca3168d9919b8bd853f5e496376708fc","observation_id":"ba6e8dbd-d2da-40dc-9db7-14d0e308fd29","resolution":{"observed_at":"2026-07-04T04:09:34.792750Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2606.29602","last_updated":"2026-06-28T20:56:57Z","snapshot_observed_at":"2026-08-07T21:01:36.927507Z","submitted_at":"2026-06-28T20:56:57Z","title":"An Empirical Evaluation of Prompt Injection Vulnerabilities in Large Language Models Across Multilingual and Obfuscated Attack Scenarios","version":1},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-06-30T06:51:43.219551Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2606.29602"},"observation_digest":"sha256:b2a44a3977dfd42c7fbfea90509d0b5c0f1fc689f977a55daccb00dfcb296646","observation_id":"57a91a59-846d-452b-86ec-c4b997c455f6","resolution":{"observed_at":"2026-06-30T06:54:20.370458Z","resolver_source":"arxiv_id","status":"metadata_mismatch"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":"2308.06463","doi":null,"metadata_source":"pith","pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-09T10:26:11.073540Z","title":"Gpt- 4 is too smart to be safe: Stealthy chat with llms via cipher","venue":"cs.CL","work_id":"c0bea3ab-35ce-4045-8b4f-46d34943d688","year":2023},"citing_paper":{"arxiv_id":"2607.07461","last_updated":"2026-07-08T14:29:23Z","snapshot_observed_at":"2026-08-08T05:41:46.659709Z","submitted_at":"2026-07-08T14:29:23Z","title":"Mitigating Taint-Style Vulnerabilities in MCP Servers via Security-Aware Tool Descriptions","version":1},"reference_index":67,"source":"pdf_text","source_observed_at":"2026-07-09T10:22:23.782469Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2607.07461"},"observation_digest":"sha256:cb0652aa64b2e48953746f4c2f9bc3102d2e9754d0689c288b75b3dcc402dd5f","observation_id":"962a42cb-4562-4ad7-841a-b05e624492e8","resolution":{"observed_at":"2026-07-09T10:26:11.075003Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-12T06:34:41.77262+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-07-14T07:16:57.009797Z","title":"Gpt-4 is too smart to be safe: Stealthy chat with llms via cipher.arXiv preprint arXiv:2308.06463, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2607.11070","last_updated":"2026-07-13T04:19:37Z","snapshot_observed_at":"2026-08-07T05:32:49.065984Z","submitted_at":"2026-07-13T04:19:37Z","title":"MJ: Multi-turn LLM Jailbreaking via Decomposed Credit Assignment","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-07-14T07:16:57.009797Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2607.11070"},"observation_digest":"sha256:7f3c374ebb371bdb4f04abf12abbd0c3617c55251d6e5b9bc23c5df4b2a581bc","observation_id":"62146656-85ba-4c8c-84a4-d3c713cab06b","resolution":{"observed_at":"2026-07-14T07:16:57.009797Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2308.06463","snapshot_observed_at":"2026-08-02T10:20:56.070529Z","title":"arXiv preprint arXiv:2308.06463 , year=","venue":null,"work_id":null,"year":null},"citing_paper":{"arxiv_id":"2607.22643","last_updated":"2026-06-24T02:40:49Z","snapshot_observed_at":"2026-08-08T03:20:50.943223Z","submitted_at":"2026-06-24T02:40:49Z","title":"Reason Before You Retrieve: Agentic Planning for Multi-modal RAG","version":1},"reference_index":110,"source":"arxiv_source","source_observed_at":"2026-08-02T10:20:56.070529Z"},"links":{"cited_paper":"/paper/2308.06463","citing_paper":"/paper/2607.22643"},"observation_digest":"sha256:9d637aec06a71b16724f80a3aff7bf34bcea82861f8484c530ff32a63e3206a9","observation_id":"4fe603d7-2991-42d2-8292-8dd403e39b73","resolution":{"observed_at":"2026-08-02T10:20:56.070529Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"links":{"evidence":"/evidence","html":"/paper/2308.06463/citation-record","integrity":"/paper/2308.06463/integrity","json":"/paper/2308.06463/citation-record.json","paper":"/paper/2308.06463"},"outbound":[],"paper":{"arxiv_id":"2308.06463","last_updated":"2024-03-26T04:23:12Z","latest_version":2,"primary_category":"cs.CL","snapshot_observed_at":"2026-07-06T16:05:31.757410Z","submitted_at":"2023-08-12T04:05:57Z","title":"GPT-4 Is Too Smart To Be Safe: Stealthy Chat with LLMs via Cipher"},"reference_resolution":{"displayed":0,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":0,"unresolved":0,"verified_exact":0,"verified_fuzzy":0},"total_outbound_references":0},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-12T06:34:41.77262+00:00","source":"crossref"},{"observed_at":"2026-08-12T06:34:36.333875+00:00","source":"retraction_watch"}],"thesis":"As of 12 August 2026, this Paper Citation Record lists 0 of 0 outbound references and 63 inbound Pith citation observations for arXiv:2308.06463."}